arXiv:2507.09095cs.LG2025-07被引 5

攻击自动驾驶多模态感知的时间同步,引发严重误判

Temporal Misalignment Attacks against Multimodal Perception in Autonomous Driving

  • 利用车内网络制造微妙时间错位,破坏摄像头与激光雷达融合
  • 单帧激光雷达延迟致车辆检测准确率下降88.5%,三帧摄像头延迟致追踪准确率降73%
  • 真实车端测试验证攻击可行性,适合安全研究与自动驾驶防御者关注

多模态融合(MMF)在自动驾驶感知中至关重要,主要融合相机与激光雷达数据以实现全面高效的场景理解。然而,其对精确时间同步的依赖使其面临新威胁。本文提出DejaVu攻击,通过车载网络篡改时间完整性,制造细微的时间错位,严重损害基于MMF的下游感知任务。跨不同模型与数据集的分析显示,各任务对传感器敏感度不均:目标检测过度依赖激光雷达,目标追踪高度依赖相机。仅需一帧激光雷达延迟,即可使车辆检测的mAP下降88.5%;三帧相机延迟则导致车辆多目标追踪准确率(MOTA)下降73%。我们在汽车以太网测试平台进行软硬件协同验证,并使用Autoware栈完成端到端自动驾驶仿真,证明了DejaVu攻击的可行性及其严重后果,如碰撞和虚报刹车。代码与实验材料已公开于:https://github.com/shahriar0651/DejaVu。

原文摘要 · Abstract (English)

Multimodal fusion (MMF) plays a critical role in the perception of autonomous driving, which primarily fuses camera and LiDAR streams for a comprehensive and efficient scene understanding. However, its strict reliance on precise temporal synchronization exposes it to new vulnerabilities. In this paper, we introduce DejaVu, an attack that exploits the in-vehicular network to manipulate the integrity of time and create subtle temporal misalignments, severely degrading downstream MMF-based perception tasks. Our comprehensive attack analysis across different models and datasets reveals the sensors' task-specific imbalanced sensitivities: object detection is overly dependent on LiDAR inputs, while object tracking is highly reliant on the camera inputs. Consequently, with a single-frame LiDAR delay, an attacker can reduce the car detection mAP by up to 88.5%, while with a three-frame camera delay, multiple object tracking accuracy (MOTA) for car drops by 73%. We further demonstrated two attack scenarios using an automotive Ethernet testbed for hardware-in-the-loop validation and the Autoware stack for end-to-end AD simulation, demonstrating the feasibility of the DejaVu attack and its severe impact, such as collisions and phantom braking. Our code and artifacts are publicly available at: https://github.com/shahriar0651/DejaVu.

自动驾驶多模态攻击时间错位安全漏洞

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。